\relax 
\providecommand\hyper@newdestlabel[2]{}
\providecommand\HyperFirstAtBeginDocument{\AtBeginDocument}
\HyperFirstAtBeginDocument{\ifx\hyper@anchor\@undefined
\global\let\oldcontentsline\contentsline
\gdef\contentsline#1#2#3#4{\oldcontentsline{#1}{#2}{#3}}
\global\let\oldnewlabel\newlabel
\gdef\newlabel#1#2{\newlabelxx{#1}#2}
\gdef\newlabelxx#1#2#3#4#5#6{\oldnewlabel{#1}{{#2}{#3}}}
\AtEndDocument{\ifx\hyper@anchor\@undefined
\let\contentsline\oldcontentsline
\let\newlabel\oldnewlabel
\fi}
\fi}
\global\let\hyper@last\relax 
\gdef\HyperFirstAtBeginDocument#1{#1}
\providecommand\HyField@AuxAddToFields[1]{}
\providecommand\HyField@AuxAddToCoFields[2]{}
\citation{mcmahan2017communication,tan2022fedproto}
\citation{zizzo2020fat,lyu2022privacy,zhou2020adversarially}
\citation{yang2019federated}
\citation{madry2017towards}
\citation{madry2017towards}
\citation{zizzo2020fat,kairouz2021advances,chen2022gear}
\citation{zizzo2020fat,kairouz2021advances,chen2022gear}
\citation{Wang_Xu_Liu_Li_Thuraisingham_Tang_2022}
\citation{goodfellow2014explaining}
\citation{shafahi2018adversarial}
\citation{kim2023demystifying}
\citation{chen2022gear,chen2022calfat,zhu2023combating,zhang2023delving}
\@LN@col{1}
\@writefile{toc}{\contentsline {section}{\numberline {1}\hskip -1em.\nobreakspace  {}Introduction}{1}{section.1}\protected@file@percent }
\newlabel{sec:intro}{{1}{1}{\hskip -1em.~Introduction}{section.1}{}}
\newlabel{sec:intro@cref}{{[section][1][]1}{[1][1][]1}}
\@writefile{brf}{\backcite{mcmahan2017communication}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{tan2022fedproto}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{lyu2022privacy}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{zhou2020adversarially}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{zizzo2020fat}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{yang2019federated}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{madry2017towards}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{madry2017towards}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{chen2022gear}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{kairouz2021advances}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{zizzo2020fat}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{chen2022gear}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{kairouz2021advances}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{zizzo2020fat}{{1}{1}{section.1}}}
\@LN@col{2}
\@writefile{brf}{\backcite{Wang_Xu_Liu_Li_Thuraisingham_Tang_2022}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{goodfellow2014explaining}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{shafahi2018adversarial}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{kim2023demystifying}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{chen2022calfat}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{chen2022gear}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{zhang2023delving}{{1}{1}{section.1}}}
\@writefile{brf}{\backcite{zhu2023combating}{{1}{1}{section.1}}}
\citation{kim2023demystifying}
\citation{kim2023demystifying}
\citation{mcmahan2017communication}
\citation{liang2021fedrec++,liu2021fedct,liu2021fedct}
\citation{kairouz2021advances}
\citation{zizzo2020fat}
\citation{zhang2023delving}
\citation{chen2022calfat}
\@LN@col{1}
\@writefile{lof}{\contentsline {figure}{\numberline {1}{\ignorespaces Test accuracy reduces for adversarially trained model under non-IID data and IID data. Meanwhile, non-IID data distributions hurts the performance. When the data distribution is non-IID, the transparent lines represent the actual test results, while the opaque lines represent sliding average to reduce fluctuations. \relax }}{2}{figure.caption.1}\protected@file@percent }
\providecommand*\caption@xref[2]{\@setref\relax\@undefined{#1}}
\newlabel{fig1}{{1}{2}{Test accuracy reduces for adversarially trained model under non-IID data and IID data. Meanwhile, non-IID data distributions hurts the performance. When the data distribution is non-IID, the transparent lines represent the actual test results, while the opaque lines represent sliding average to reduce fluctuations. \relax }{figure.caption.1}{}}
\newlabel{fig1@cref}{{[figure][1][]1}{[1][2][]2}}
\@writefile{brf}{\backcite{kim2023demystifying}{{2}{1}{figure.caption.1}}}
\@writefile{brf}{\backcite{kim2023demystifying}{{2}{1}{figure.caption.1}}}
\@LN@col{2}
\@writefile{toc}{\contentsline {section}{\numberline {2}\hskip -1em.\nobreakspace  {}Related Work and Preliminaries}{2}{section.2}\protected@file@percent }
\@writefile{toc}{\contentsline {subsection}{\numberline {2.1}\hskip -1em.\nobreakspace  {}Federated Learning}{2}{subsection.2.1}\protected@file@percent }
\@writefile{brf}{\backcite{mcmahan2017communication}{{2}{2.1}{subsection.2.1}}}
\@writefile{brf}{\backcite{liang2021fedrec++}{{2}{2.1}{subsection.2.1}}}
\@writefile{brf}{\backcite{liu2021fedct}{{2}{2.1}{subsection.2.1}}}
\@writefile{brf}{\backcite{liu2021fedct}{{2}{2.1}{subsection.2.1}}}
\@writefile{brf}{\backcite{kairouz2021advances}{{2}{2.1}{subsection.2.1}}}
\@writefile{toc}{\contentsline {subsection}{\numberline {2.2}\hskip -1em.\nobreakspace  {}Federated Adversarial Training}{2}{subsection.2.2}\protected@file@percent }
\@writefile{brf}{\backcite{zizzo2020fat}{{2}{2.2}{subsection.2.2}}}
\@writefile{brf}{\backcite{zhang2023delving}{{2}{2.2}{subsection.2.2}}}
\@writefile{brf}{\backcite{chen2022calfat}{{2}{2.2}{subsection.2.2}}}
\citation{runde1998assessing,bloom2001cumulative,sebri2014causal,omri2015modeling}
\citation{reiersol1945confluence}
\citation{bennett2019deep,dikkala2020minimax}
\citation{hansen1982large}
\citation{zhao2018federated,luo2019real}
\citation{hsieh2020non,chen2022calfat}
\@LN@col{1}
\newlabel{local adversarial training}{{1}{3}{\hskip -1em.~Federated Adversarial Training}{equation.2.1}{}}
\newlabel{local adversarial training@cref}{{[equation][1][]1}{[1][3][]3}}
\newlabel{FAT}{{2}{3}{\hskip -1em.~Federated Adversarial Training}{equation.2.2}{}}
\newlabel{FAT@cref}{{[equation][2][]2}{[1][3][]3}}
\@writefile{toc}{\contentsline {subsection}{\numberline {2.3}\hskip -1em.\nobreakspace  {}Causal Inference}{3}{subsection.2.3}\protected@file@percent }
\@writefile{brf}{\backcite{bloom2001cumulative}{{3}{2.3}{subsection.2.3}}}
\@writefile{brf}{\backcite{omri2015modeling}{{3}{2.3}{subsection.2.3}}}
\@writefile{brf}{\backcite{runde1998assessing}{{3}{2.3}{subsection.2.3}}}
\@writefile{brf}{\backcite{sebri2014causal}{{3}{2.3}{subsection.2.3}}}
\@writefile{brf}{\backcite{reiersol1945confluence}{{3}{2.3}{subsection.2.3}}}
\@writefile{brf}{\backcite{bennett2019deep}{{3}{2.3}{subsection.2.3}}}
\@writefile{brf}{\backcite{dikkala2020minimax}{{3}{2.3}{subsection.2.3}}}
\@LN@col{2}
\newlabel{GMM}{{3}{3}{\hskip -1em.~Causal Inference}{equation.2.3}{}}
\newlabel{GMM@cref}{{[equation][3][]3}{[1][3][]3}}
\newlabel{EuTheta}{{4}{3}{\hskip -1em.~Causal Inference}{equation.2.4}{}}
\newlabel{EuTheta@cref}{{[equation][4][]4}{[1][3][]3}}
\@writefile{brf}{\backcite{hansen1982large}{{3}{2.3}{equation.2.4}}}
\newlabel{OWGMM}{{5}{3}{\hskip -1em.~Causal Inference}{equation.2.5}{}}
\newlabel{OWGMM@cref}{{[equation][5][]5}{[1][3][]3}}
\newlabel{DeepGMM}{{6}{3}{\hskip -1em.~Causal Inference}{equation.2.6}{}}
\newlabel{DeepGMM@cref}{{[equation][6][]6}{[1][3][]3}}
\@writefile{toc}{\contentsline {section}{\numberline {3}\hskip -1em.\nobreakspace  {}Methodology}{3}{section.3}\protected@file@percent }
\@writefile{toc}{\contentsline {subsection}{\numberline {3.1}\hskip -1em.\nobreakspace  {}Label Distribution}{3}{subsection.3.1}\protected@file@percent }
\@writefile{brf}{\backcite{luo2019real}{{3}{3.1}{subsection.3.1}}}
\@writefile{brf}{\backcite{zhao2018federated}{{3}{3.1}{subsection.3.1}}}
\@writefile{brf}{\backcite{chen2022calfat}{{3}{3.1}{subsection.3.1}}}
\@writefile{brf}{\backcite{hsieh2020non}{{3}{3.1}{subsection.3.1}}}
\citation{kim2023demystifying,bennett2019deep}
\citation{glymour2003learning,gopnik2004theory,lattimore2019causal}
\citation{lattimore2019causal}
\citation{pearl2000models}
\citation{kim2023demystifying}
\citation{bennett2019deep,kim2023demystifying}
\@LN@col{1}
\@writefile{brf}{\backcite{bennett2019deep}{{4}{3.1}{subsection.3.1}}}
\@writefile{brf}{\backcite{kim2023demystifying}{{4}{3.1}{subsection.3.1}}}
\newlabel{prop1}{{8}{4}{\hskip -1em.~Label Distribution}{equation.3.8}{}}
\newlabel{prop1@cref}{{[equation][8][]8}{[1][4][]4}}
\@writefile{toc}{\contentsline {subsection}{\numberline {3.2}\hskip -1em.\nobreakspace  {}Federated Adversarial GMM}{4}{subsection.3.2}\protected@file@percent }
\@writefile{brf}{\backcite{glymour2003learning}{{4}{3.2}{subsection.3.2}}}
\@writefile{brf}{\backcite{gopnik2004theory}{{4}{3.2}{subsection.3.2}}}
\@writefile{brf}{\backcite{lattimore2019causal}{{4}{3.2}{subsection.3.2}}}
\@writefile{brf}{\backcite{lattimore2019causal}{{4}{3.2}{subsection.3.2}}}
\newlabel{bayes}{{9}{4}{\hskip -1em.~Federated Adversarial GMM}{equation.3.9}{}}
\newlabel{bayes@cref}{{[equation][9][]9}{[1][4][]4}}
\@LN@col{2}
\@writefile{brf}{\backcite{pearl2000models}{{4}{3.2}{equation.3.9}}}
\newlabel{calfat}{{10}{4}{\hskip -1em.~Federated Adversarial GMM}{equation.3.10}{}}
\newlabel{calfat@cref}{{[equation][10][]10}{[1][4][]4}}
\@writefile{brf}{\backcite{kim2023demystifying}{{4}{3.2}{equation.3.10}}}
\@writefile{brf}{\backcite{bennett2019deep}{{4}{3.2}{equation.3.10}}}
\@writefile{brf}{\backcite{kim2023demystifying}{{4}{3.2}{equation.3.10}}}
\newlabel{GMM-1}{{11}{4}{\hskip -1em.~Federated Adversarial GMM}{equation.3.11}{}}
\newlabel{GMM-1@cref}{{[equation][11][]11}{[1][4][]4}}
\newlabel{yy}{{12}{4}{\hskip -1em.~Federated Adversarial GMM}{equation.3.12}{}}
\newlabel{yy@cref}{{[equation][12][]12}{[1][4][]4}}
\citation{zhu2023combating}
\citation{hong2021federated,li2021fedbn}
\citation{Schneider_Rusak_Eck_Bringmann_Brendel_Bethge_2020}
\citation{krizhevsky2009learning}
\citation{krizhevsky2009learning}
\citation{netzer2011reading}
\citation{le2015tiny}
\citation{yurochkin2019bayesian}
\citation{Simonyan_Zisserman_2015}
\citation{He_Zhang_Ren_Sun_2016}
\citation{Zagoruyko_Komodakis_2016}
\citation{zizzo2020fat}
\citation{chen2022calfat}
\citation{zhang2023delving}
\citation{chen2022gear}
\citation{zhu2023combating}
\citation{goodfellow2014explaining}
\citation{madry2017towards}
\citation{Carlini_Wagner_2017}
\citation{madry2017towards}
\citation{Robbins_Monro}
\citation{Smith_2017}
\@LN@col{1}
\newlabel{Local Ob}{{14}{5}{\hskip -1em.~Federated Adversarial GMM}{equation.3.14}{}}
\newlabel{Local Ob@cref}{{[equation][14][]14}{[1][5][]5}}
\@writefile{toc}{\contentsline {subsection}{\numberline {3.3}\hskip -1em.\nobreakspace  {}Model Aggregation}{5}{subsection.3.3}\protected@file@percent }
\@writefile{brf}{\backcite{zhu2023combating}{{5}{3.3}{subsection.3.3}}}
\@writefile{brf}{\backcite{hong2021federated}{{5}{3.3}{subsection.3.3}}}
\@writefile{brf}{\backcite{li2021fedbn}{{5}{3.3}{subsection.3.3}}}
\@writefile{brf}{\backcite{Schneider_Rusak_Eck_Bringmann_Brendel_Bethge_2020}{{5}{3.3}{subsection.3.3}}}
\@LN@col{2}
\@writefile{lof}{\contentsline {figure}{\numberline {2}{\ignorespaces The distribution of client dataset simulated by Dirichlet partition function. \relax }}{5}{figure.caption.4}\protected@file@percent }
\newlabel{fig2}{{2}{5}{The distribution of client dataset simulated by Dirichlet partition function. \relax }{figure.caption.4}{}}
\newlabel{fig2@cref}{{[figure][2][]2}{[1][5][]5}}
\@writefile{lof}{\contentsline {figure}{\numberline {3}{\ignorespaces The effect of causal adversarial training before and after label skewed information is introduced.\relax }}{5}{figure.caption.5}\protected@file@percent }
\newlabel{skewed ablation}{{3}{5}{The effect of causal adversarial training before and after label skewed information is introduced.\relax }{figure.caption.5}{}}
\newlabel{skewed ablation@cref}{{[figure][3][]3}{[1][5][]5}}
\@writefile{toc}{\contentsline {section}{\numberline {4}\hskip -1em.\nobreakspace  {}Experiments}{5}{section.4}\protected@file@percent }
\@writefile{brf}{\backcite{krizhevsky2009learning}{{5}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{krizhevsky2009learning}{{5}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{netzer2011reading}{{5}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{le2015tiny}{{5}{4}{figure.caption.5}}}
\citation{zizzo2020fat}
\citation{chen2022calfat}
\@writefile{lot}{\contentsline {table}{\numberline {1}{\ignorespaces \textbf  {Experimental Results}\relax }}{6}{table.caption.2}\protected@file@percent }
\newlabel{BN table}{{1}{6}{\textbf {Experimental Results}\relax }{table.caption.2}{}}
\newlabel{BN table@cref}{{[table][1][]1}{[1][5][]6}}
\@writefile{lot}{\contentsline {table}{\numberline {2}{\ignorespaces \textbf  {Experimental Results}\relax }}{6}{table.caption.3}\protected@file@percent }
\newlabel{experimental results}{{2}{6}{\textbf {Experimental Results}\relax }{table.caption.3}{}}
\newlabel{experimental results@cref}{{[table][2][]2}{[1][5][]6}}
\@LN@col{1}
\@writefile{brf}{\backcite{yurochkin2019bayesian}{{6}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{Simonyan_Zisserman_2015}{{6}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{He_Zhang_Ren_Sun_2016}{{6}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{Zagoruyko_Komodakis_2016}{{6}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{zizzo2020fat}{{6}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{chen2022calfat}{{6}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{zhang2023delving}{{6}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{chen2022gear}{{6}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{zhu2023combating}{{6}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{goodfellow2014explaining}{{6}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{madry2017towards}{{6}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{Carlini_Wagner_2017}{{6}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{madry2017towards}{{6}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{Robbins_Monro}{{6}{4}{figure.caption.5}}}
\@writefile{brf}{\backcite{Smith_2017}{{6}{4}{figure.caption.5}}}
\@LN@col{2}
\@writefile{toc}{\contentsline {section}{\numberline {5}\hskip -1em.\nobreakspace  {}Ablation Studies}{6}{section.5}\protected@file@percent }
\@writefile{brf}{\backcite{zizzo2020fat}{{6}{5}{section.5}}}
\@writefile{brf}{\backcite{chen2022calfat}{{6}{5}{section.5}}}
\citation{van2008visualizing}
\@LN@col{1}
\@writefile{lot}{\contentsline {table}{\numberline {3}{\ignorespaces \textbf  {Ablation of Aggregation's Results}\relax }}{7}{table.caption.6}\protected@file@percent }
\newlabel{BN table}{{3}{7}{\textbf {Ablation of Aggregation's Results}\relax }{table.caption.6}{}}
\newlabel{BN table@cref}{{[table][3][]3}{[1][7][]7}}
\@writefile{lof}{\contentsline {figure}{\numberline {4}{\ignorespaces  The causal model with aggregation is better than the causal model without aggregation. However, our BN layer aggregation algorithm, at a very small extra communication cost, can achieve results similar to all parameters of the aggregate causal model.\relax }}{7}{figure.caption.7}\protected@file@percent }
\newlabel{aggregation compration}{{4}{7}{The causal model with aggregation is better than the causal model without aggregation. However, our BN layer aggregation algorithm, at a very small extra communication cost, can achieve results similar to all parameters of the aggregate causal model.\relax }{figure.caption.7}{}}
\newlabel{aggregation compration@cref}{{[figure][4][]4}{[1][7][]7}}
\@LN@col{2}
\@writefile{lof}{\contentsline {figure}{\numberline {5}{\ignorespaces T-nse visualization.\relax }}{7}{figure.caption.8}\protected@file@percent }
\newlabel{T-nse visualization}{{5}{7}{T-nse visualization.\relax }{figure.caption.8}{}}
\newlabel{T-nse visualization@cref}{{[figure][5][]5}{[1][7][]7}}
\@writefile{lof}{\contentsline {figure}{\numberline {6}{\ignorespaces Feature visualization, the darker the area, the lower the impact on classification.\relax }}{7}{figure.caption.9}\protected@file@percent }
\newlabel{Feature visualization}{{6}{7}{Feature visualization, the darker the area, the lower the impact on classification.\relax }{figure.caption.9}{}}
\newlabel{Feature visualization@cref}{{[figure][6][]6}{[1][7][]7}}
\@writefile{brf}{\backcite{van2008visualizing}{{7}{5}{figure.caption.9}}}
\@writefile{toc}{\contentsline {section}{\numberline {6}\hskip -1em.\nobreakspace  {}Conclusion}{7}{section.6}\protected@file@percent }
\bibstyle{ieeenat_fullname}
\bibdata{main}
\bibcite{bennett2019deep}{{1}{2019}{{Bennett et~al.}}{{Bennett, Kallus, and Schnabel}}}
\bibcite{bloom2001cumulative}{{2}{2001}{{Bloom and Canning}}{{}}}
\bibcite{Carlini_Wagner_2017}{{3}{2017}{{Carlini and Wagner}}{{}}}
\bibcite{chen2022calfat}{{4}{2022{}}{{Chen et~al.}}{{Chen, Liu, Ma, and Lyu}}}
\bibcite{chen2022gear}{{5}{2022{}}{{Chen et~al.}}{{Chen, Zhang, and Lyu}}}
\bibcite{dikkala2020minimax}{{6}{2020}{{Dikkala et~al.}}{{Dikkala, Lewis, Mackey, and Syrgkanis}}}
\bibcite{glymour2003learning}{{7}{2003}{{Glymour}}{{}}}
\bibcite{goodfellow2014explaining}{{8}{2014}{{Goodfellow et~al.}}{{Goodfellow, Shlens, and Szegedy}}}
\bibcite{gopnik2004theory}{{9}{2004}{{Gopnik et~al.}}{{Gopnik, Glymour, Sobel, Schulz, Kushnir, and Danks}}}
\bibcite{hansen1982large}{{10}{1982}{{Hansen}}{{}}}
\bibcite{He_Zhang_Ren_Sun_2016}{{11}{2016}{{He et~al.}}{{He, Zhang, Ren, and Sun}}}
\bibcite{hong2021federated}{{12}{2021}{{Hong et~al.}}{{Hong, Wang, Wang, and Zhou}}}
\bibcite{hsieh2020non}{{13}{2020}{{Hsieh et~al.}}{{Hsieh, Phanishayee, Mutlu, and Gibbons}}}
\bibcite{kairouz2021advances}{{14}{2021}{{Kairouz et~al.}}{{Kairouz, McMahan, Avent, Bellet, Bennis, Bhagoji, Bonawitz, Charles, Cormode, Cummings, et~al.}}}
\bibcite{kim2023demystifying}{{15}{2023}{{Kim et~al.}}{{Kim, Lee, and Ro}}}
\@LN@col{1}
\@LN@col{2}
\bibcite{krizhevsky2009learning}{{16}{2009}{{Krizhevsky et~al.}}{{Krizhevsky, Hinton, et~al.}}}
\bibcite{lattimore2019causal}{{17}{2019}{{Lattimore and Rohde}}{{}}}
\bibcite{le2015tiny}{{18}{2015}{{Le and Yang}}{{}}}
\bibcite{li2021fedbn}{{19}{2021}{{Li et~al.}}{{Li, Jiang, Zhang, Kamp, and Dou}}}
\bibcite{liang2021fedrec++}{{20}{2021}{{Liang et~al.}}{{Liang, Pan, and Ming}}}
\bibcite{liu2021fedct}{{21}{2021}{{Liu et~al.}}{{Liu, Xu, Yu, Fu, Zhang, and Marian}}}
\bibcite{luo2019real}{{22}{2019}{{Luo et~al.}}{{Luo, Wu, Luo, Huang, Huang, Liu, and Yang}}}
\bibcite{lyu2022privacy}{{23}{2022}{{Lyu et~al.}}{{Lyu, Yu, Ma, Chen, Sun, Zhao, Yang, and Philip}}}
\bibcite{madry2017towards}{{24}{2017}{{Madry et~al.}}{{Madry, Makelov, Schmidt, Tsipras, and Vladu}}}
\bibcite{mcmahan2017communication}{{25}{2017}{{McMahan et~al.}}{{McMahan, Moore, Ramage, Hampson, and y~Arcas}}}
\bibcite{netzer2011reading}{{26}{2011}{{Netzer et~al.}}{{Netzer, Wang, Coates, Bissacco, Wu, and Ng}}}
\bibcite{omri2015modeling}{{27}{2015}{{Omri et~al.}}{{Omri, Mabrouk, and Sassi-Tmar}}}
\bibcite{pearl2000models}{{28}{2000}{{Pearl et~al.}}{{}}}
\bibcite{reiersol1945confluence}{{29}{1945}{{Reiers{\o }l}}{{}}}
\bibcite{Robbins_Monro}{{30}{}{{Robbins and Monro}}{{}}}
\bibcite{runde1998assessing}{{31}{1998}{{Runde}}{{}}}
\bibcite{Schneider_Rusak_Eck_Bringmann_Brendel_Bethge_2020}{{32}{2020}{{Schneider et~al.}}{{Schneider, Rusak, Eck, Bringmann, Brendel, and Bethge}}}
\bibcite{sebri2014causal}{{33}{2014}{{Sebri and Ben-Salha}}{{}}}
\bibcite{shafahi2018adversarial}{{34}{2018}{{Shafahi et~al.}}{{Shafahi, Huang, Studer, Feizi, and Goldstein}}}
\bibcite{Simonyan_Zisserman_2015}{{35}{2015}{{Simonyan and Zisserman}}{{}}}
\bibcite{Smith_2017}{{36}{2017}{{Smith}}{{}}}
\bibcite{tan2022fedproto}{{37}{2022}{{Tan et~al.}}{{Tan, Long, Liu, Zhou, Lu, Jiang, and Zhang}}}
\bibcite{van2008visualizing}{{38}{2008}{{Van~der Maaten and Hinton}}{{}}}
\bibcite{Wang_Xu_Liu_Li_Thuraisingham_Tang_2022}{{39}{2022}{{Wang et~al.}}{{Wang, Xu, Liu, Li, Thuraisingham, and Tang}}}
\bibcite{yang2019federated}{{40}{2019}{{Yang et~al.}}{{Yang, Liu, Chen, and Tong}}}
\bibcite{yurochkin2019bayesian}{{41}{2019}{{Yurochkin et~al.}}{{Yurochkin, Agarwal, Ghosh, Greenewald, Hoang, and Khazaeni}}}
\bibcite{Zagoruyko_Komodakis_2016}{{42}{2016}{{Zagoruyko and Komodakis}}{{}}}
\bibcite{zhang2023delving}{{43}{2023}{{Zhang et~al.}}{{Zhang, Li, Chen, Lyu, Wu, Ding, and Wu}}}
\bibcite{zhao2018federated}{{44}{2018}{{Zhao et~al.}}{{Zhao, Li, Lai, Suda, Civin, and Chandra}}}
\bibcite{zhou2020adversarially}{{45}{2020}{{Zhou et~al.}}{{Zhou, Wu, and He}}}
\bibcite{zhu2023combating}{{46}{2023}{{Zhu et~al.}}{{Zhu, Yao, Liu, Yao, Xu, and Han}}}
\bibcite{zizzo2020fat}{{47}{2020}{{Zizzo et~al.}}{{Zizzo, Rawat, Sinn, and Buesser}}}
\@LN@col{1}
\@LN@col{2}
\@LN@col{1}
\@LN@col{2}
